This is the problem isBusinessEmail was built for. A user signs up, reaches “Connect your workspace”, and only then discovers that their @gmail.com or @outlook.com account can’t do what your integration needs. Onboarding stalls, a support ticket follows. Our story.
What personal accounts can’t do
| You need | Requires | Personal account? |
|---|---|---|
| Google Workspace Admin SDK, domain-wide delegation | A Workspace organization and its admin | No: personal Gmail has no admin console |
| Shared Drives | A Workspace organization | No |
| Microsoft Graph admin consent / application permissions | An Entra ID tenant and an admin | No: personal Microsoft accounts can’t grant org-wide consent |
| SharePoint Online, OneDrive for Business, Teams org data | A Microsoft 365 tenant | No |
Use the signal at three moments
1. At signup: set expectations
If the product needs a tenant and the email is personal, say so right away: “To connect SharePoint you’ll need your work Microsoft account.” Then let them continue with a work email or explore read-only.
2. On the connect screen: pre-select the right connector
const v = await checkEmail(user.email); // stored at signup; don't re-check every time
const ms = v.workspace?.microsoft_365;
const google = v.workspace?.google_workspace;
let suggested = null;
if (ms?.detected && !google?.detected) suggested = 'microsoft';
else if (google?.detected && !ms?.detected) suggested = 'google';
// both detected: show both, Microsoft first if mail is on Exchange (reason mx_microsoft_365)
Show the suggested connector first and the other one below it. Don’t hide options: detection is a hint.
3. Admin consent: skip the “which organization?” step
With a tenant ID you can send an admin straight to the consent screen for their tenant:
const url = new URL(`https://login.microsoftonline.com/${ms.tenant_id}/v2.0/adminconsent`);
url.searchParams.set('client_id', process.env.MS_CLIENT_ID);
url.searchParams.set('scope', 'https://graph.microsoft.com/.default');
url.searchParams.set('redirect_uri', 'https://app.example.com/integrations/microsoft/callback');
url.searchParams.set('state', csrfToken);
For Google sign-in, the hd parameter hints the expected Workspace domain, and Microsoft supports domain_hint / login_hint to skip account pickers.
Federated tenants
If auth is federated with an identity_provider such as Okta, the admin who can consent is often in IT. Offer “Send this link to your admin” from the start, with the pre-filled consent URL.
What detection can’t tell you
- Whether this user is an admin, or will get consent.
- Whether they have a license for the product you integrate with.
- Whether IT policies block third-party apps.
Design for “invite your admin” anyway; detection makes the right path the default.
Try it
- Test addresses:
m365@test.isbusinessemail.com(Microsoft 365, federated via Okta) andworkspace@test.isbusinessemail.com(Google Workspace). See Test addresses. - Tools: Microsoft tenant lookup, Google Workspace checker.
Related: Workspace detection · Microsoft 365 tenant vs Outlook.com